Skip to content
MongoDBCVE-2026-13055

MongoDB Server: reachable assertion

High7.1CVE-2026-13055 · Published Jul 22, 2026 · updated Aug 5, 2026

The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard index specifications, triggering an internal consistency check that aborts the server process. The user must be able to run an aggregation pipeline.

MongoDB advisory

Affected versions

PackageAffectedFixed in
MongoDB Server
Product
>= 7.0, < 7.0.397.0.39
>= 8.0, < 8.0.288.0.28
>= 8.2.0, < 8.2.128.2.12
>= 8.3.0, < 8.3.78.3.7
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-617

More MongoDB advisories

All MongoDB
Advisory
MongoDB Server: reachable assertion
High7.1Jul 22
MongoDB Compass: command injection
High8.4Jul 22
MongoDB Server: resource exhaustion
Medium6.9Jul 22
MongoDB Server: resource exhaustion
High7.1Jul 22
MongoDB Server: resource exhaustion
High7.1Jul 22
MongoDB Server: out-of-bounds read
High7.1Jul 22

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.